Summary
When configuring a route-map, the VyOS CLI strictly validates the existence of a prefix-list referenced in a match rule. If the prefix-list is not defined beforehand, the commit fails. This strict validation breaks standard configuration workflows (especially during migrations) and is highly inconsistent with both native FRRouting behavior and how VyOS handles other policy objects (like as-path).
Steps to reproduce
Try to create a route-map that references a prefix-list that hasn't been created yet:
set policy route-map TEST rule 5 action 'permit' set policy route-map TEST rule 5 match ip address prefix-list 'PL-TEST' commit
Actual behavior
The commit fails with a validation error:
[ policy ] prefix-list PL-TEST does not exist! [[policy]] failed Commit failed
Expected behavior
The commit should succeed. The CLI should allow creating the route-map referencing a non-existent prefix-list, allowing engineers to define policy objects in an arbitrary order.
Additional information
This validation logic is overly strict and inconsistent.
Inconsistency with FRR: Doing the exact same thing directly in the FRR shell (vtysh) works without any issues. FRR permits the creation of the route-map.
vyos@BORDER1:~$ vtysh BORDER1# conf BORDER1(config)# route-map TEST permit 5 BORDER1(config-route-map)# match ip address prefix-list 'PL-TEST' BORDER1(config-route-map)#
At the same time, this works without any issue:
set policy route-map TEST rule 5 action 'permit' set policy route-map TEST rule 5 match as-path 'AS-TEST' commit # Commit succeeds
The validation script for route-map -> prefix-list needs to be relaxed to match the as-path behavior and native FRR logic.
Version: VyOS 2026.02
Build commit ID: e4c4eddad9b984